Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #9880

Re: Re: UEFI Secure Boot sprint report

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.project
Subject Re: Re: UEFI Secure Boot sprint report
Date 2018-05-14 16:40 +0200
Message-ID <vPmNP-P8-1@gated-at.bofh.it> (permalink)
References <vPloJ-7j-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Mon, 2018-05-14 at 22:05 +0900, Hideki Yamane wrote:
> Hi,
> 
>  Thanks, your explanation is really helpful.
> 
> 
> > The signing service is a source package builder.
> 
>  It build source package but its source package is based on built binary package?
>  As I understand, singing to binary is necessary step.

Right.

> 1. source package
> 2. -> upload to dak
> 3. -> passed to buildd
> 4. -> binary package built

And one of those binary packages is a "template" for the source
package.  This is documented on the Etherpad, but in short it contains
an unpacked source package with everything except the signatures, plus
a configuration file specifying which binaries in which packages need
to be signed.

> 5. -> singing service pull those
> 6. -> source package built

This is the template source package plus all the (detached) signatures
that were specified in the configuration.

> 7. -> dak, again
> 8. -> buildd, again

Here there are build-dependencies on the previously built binaries, and
the build process adds the detached signatures to those binaries.

> 9. -> dak passes those to repo 
> 
> 
>  And in previous report 
> 
> > We're still missing (partially or completely):
> > - generate a signing template for GRUB2
> > - have DAK accept those generated source-only uploads
> 
>  This is 7th step in above, right? 

The second point (have DAK accept ...) is part of step 7, yes.  It
seems to have been implemented now.

Ben.

-- 
Ben Hutchings
For every action, there is an equal and opposite criticism. - Harrison

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@debian.org> - 2018-04-29 21:50 +0200
  Re: UEFI Secure Boot sprint report Ian Jackson <ijackson@chiark.greenend.org.uk> - 2018-04-30 14:20 +0200
    Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-04-30 17:30 +0200
  Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-07 15:40 +0200
    Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-05-13 16:20 +0200
      Re: Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-14 15:10 +0200
        Re: Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-14 16:40 +0200
          Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:10 +0200
            Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-15 04:40 +0200
              Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:50 +0200
                Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-05-15 05:20 +0200
                Re: UEFI Secure Boot sprint report Steve McIntyre <steve@einval.com> - 2018-05-15 11:50 +0200
                Re: UEFI Secure Boot sprint report Philipp Hahn <hahn@univention.de> - 2018-05-16 10:30 +0200
                Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-17 01:30 +0200
                Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-06-19 01:00 +0200
                Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-06-19 10:30 +0200
                Re: UEFI Secure Boot - GRUB WIP report Philipp Hahn <hahn@univention.de> - 2018-06-19 11:20 +0200
                Re: UEFI Secure Boot - GRUB WIP report Colin Watson <cjwatson@debian.org> - 2018-06-19 15:00 +0200
  Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-10-02 14:40 +0200

csiph-web